Analysis result management device, analysis result management method and program therefor

The analysis result management device addresses the redundancy of warnings across different static analysis tools by calculating a unique hash value for each warning, enhancing software development efficiency by eliminating duplicate warnings and facilitating effective verification.

DE102024136394A1Pending Publication Date: 2025-06-26DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102024136394
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In software development, as the size and complexity of software increase, coding errors lead to numerous warnings that are often redundantly identified across different static analysis tools, reducing work efficiency and making it difficult for developers to verify the contents of warnings.

Method used

An analysis result management device that manages data of static analysis results from multiple tools by calculating a hash value for each warning, using identification information to identify and store warnings uniquely, thereby preventing duplication and allowing efficient verification.

Benefits of technology

This approach enables developers to efficiently manage and verify analysis results by treating identical warnings as a single entity, reducing redundant checks and improving work efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An analysis result management device (3) that manages static analysis results obtained by different analysis tools includes: a table (18) containing a plurality of different warning descriptions generated according to the same type of warning and identification information associated with the respective different warning descriptions; an input unit (11) that receives the static analysis results of the source code analyzed by the different analysis tools; a hash value calculation unit (14) that, in response to a determination that one of the plurality of different warning descriptions corresponds to a target warning, calculates a hash value for the target warning for which the hash value is to be calculated using the identification information; a database (15) that stores data of the target warning in association with the calculated hash value;and a display unit (16) that displays the data stored in the database;
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to an analysis result management apparatus that manages analysis results of a source code.In software development, coding errors often result in improper operation of software. Although it is possible to prevent improper operation by checking the source code, the number of errors increases dramatically as the size and complexity of the software increases.In order to detect such errors before performing a test of the program, static analysis systems have been developed and are commercially available. The static analysis system syntactically and semantically analyzes software source files without actually executing the software source files, and outputs warnings to describe source codes that may contain bugs. This type of analysis system outputs the information such that a software developer can use the outputted information to correct the source code.The analysis system outputs an analysis result of the source code. In some cases, the analysis result includes a large number of warnings. When multiple versions of software programs are generated in software development and a warning that has already been confirmed in a previous version is output again in a subsequent version, the software developer needs to confirm the warning again even if the warning has already been confirmed in the previous version. This can reduce the working efficiency. JP 2004-126 866 A discloses a technique for suppressing warning messages by comparing row and column numbers of a source code, an analysis target syntax, and components included in the syntax between the previous version of the software code and the subsequent version of the software code.A system is known that calculates a hash value for a set of a source code description content and a tool acquisition result, and manages the analysis result using the hash value. The use of the hash value makes it easy to compare analysis results for different versions of the source code. Since the analysis results can be treated equally with the same hash value, reuse of the analysis result becomes possible. The alerts may be searched using the hash value, thereby increasing work efficiency and management accuracy.When the source code is analyzed, several different static analysis systems may be used. Since a plurality of static analysis systems perform analysis from different perspectives, detection accuracy of errors of the source code can be improved.When the different static analysis systems are used to detect respective errors, multiple different warnings may be issued for the same type of code error. This can increase the number of warnings and make it difficult for a software developer to check the contents of the warnings.In view of this, it is an object of the present invention to provide a technique that can determine analysis results of a source code as appropriate.In order to solve the above problem, the present invention includes the following aspects.According to an aspect of the present invention, an analysis result management device manages data of static analysis results obtained by analyzing a source code using different analysis tools. The analysis result management device includes a table including a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table also including identification information associated with the respective different warning descriptions. The analysis result management device includes an input unit that receives the data of the static analysis results of the source code analyzed by the different analysis tools. The analysis result management device includes a hash value calculation unit that acquires warning data including information regarding a target warning included in the received static analysis results and calculates a hash value for the target warning by referring to the table. The target warning is a warning for which the hash value is to be calculated. The hash value calculation unit calculates, in response to a determination that one of the different warning descriptions corresponds to the target warning, the hash value for the target warning using the identification information associated with the one of the plurality of different warning descriptions in the table without using the one of the plurality of different warning descriptions. The analysis result management device includes a database storing data of the target warning in association with the hash value calculated for the target warning, and a display unit displaying the data stored in the database.According to another aspect of the present invention, a computer-implemented analysis result management method manages data of static analysis results obtained by analyzing a source code using different analysis tools using an analysis result management device. The analysis result management method includes: preparing, by the analysis result management device, a table including a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table further including identification information associated with the respective different warning descriptions; receiving, by the analysis result management device, the data of static analysis results of the source code analyzed by the different analysis tools; acquiring, by the analysis result management device, warning data including information regarding a target warning included in the received static analysis results; calculating, by reference to the table, a hash value for the target warning, the target warning being a warning for which the hash value is to be calculated; in response to a determination that one of the plurality of different alert descriptions corresponds to the target alert, calculating the hash value for the target alert using the identification information associated with the one of the plurality of different alert descriptions in the table without using the one of the plurality of different alert descriptions; storing data of the target alert associated with the hash value calculated for the target alert in a database; and displaying the data stored in the database.According to another aspect of the present invention, a computer program for managing data of static analysis results obtained by analyzing a source code using different analysis tools causes a computer to function as: a table including a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table further including identification information associated with the respective different warning descriptions; an input unit receiving the data of static analysis results of the source code analyzed by the different analysis tools; a hash value calculation unit that acquires warning data including information regarding a target warning included in the received static analysis results and calculates a hash value for the target warning by referring to the table, the target warning being a warning for which the hash value is to be calculated, wherein the hash value calculation unit calculates, in response to a determination that one of the plurality of different warning descriptions corresponds to the target warning, the hash value for the target warning using the identification information associated with the one of the plurality of different warning descriptions in the table without using the one of the plurality of different warning descriptions; a database storing data of the target warning in association with the hash value calculated for the target warning; and a display unit displaying the data stored in the database.According to the above aspects of the present invention, display of duplicated warnings for different static analysis results analyzed by the different analysis tools can be prevented, thereby allowing a software developer to appropriately evaluate the different analysis results of the source code.Other objects and advantages of the present invention will become apparent from the following detailed description with reference to the accompanying drawings. The following are shown: FIG. 1 is a diagram showing a functional configuration of an analysis result management device according to a first embodiment; FIG. 2 is a diagram showing a hardware configuration of the analysis result management device according to the first embodiment; FIG. 3A is a diagram showing an example of static analysis result data stored in a database; FIG. 3B is a diagram showing an example of check result data stored in a database; FIG. 4 is a diagram showing an example of a source code which is a target of static analysis; FIG. 5A is a diagram showing the code used to calculate a hash value of a warning in the warning line 1; FIG. 5B is a diagram showing the code used to calculate a hash value of a warning in the warning line 2; FIG. 5C is a diagram showing the code used to calculate a hash value of a warning in the warning line 3; FIG. 6 is a flowchart showing a calculation process performed by a hash value calculation unit; FIG. 7A is a diagram showing the code used to calculate a hash value of a warning in the warning line 1; FIG. 7B is a diagram showing the code used to calculate a hash value of a warning in the warning line 2; FIG. 7C is a diagram showing the code used to calculate a hash value of a warning in the warning line 3; FIG. 8 is a diagram showing another example of hash value calculation performed by a hash value calculation unit; FIG. 9 is a diagram explaining a calculation process performed by a hash value calculation unit of an analysis result management device according to a second embodiment; FIG. 10 is a diagram showing a functional configuration of an analysis result management device according to a third embodiment; FIG. 11 is a diagram showing an example of data stored in a warning correspondence table; FIG. 12 is a diagram explaining a calculation process performed by a hash value calculation unit; FIG. 13 is a diagram showing an example of a screen displaying an analysis result managed by an analysis result management device; FIG. 14 is a diagram explaining a calculation process performed by a hash value calculation unit of an analysis result management device according to a third embodiment; and FIG. 15 is a diagram showing types of inputs used for calculating hash values in different calculation methods.Next, an analysis result management apparatus according to the present invention will be described with reference to the drawings.First EmbodimentOverall Configuration of Analysis Result Management DeviceFIG. 1 is a diagram showing a functional configuration of an analysis result management device 1 according to the present embodiment. The analysis result management device 1 receives an analysis result of a software source code managed by a static analysis tool 20 as an input, and manages the received static analysis result data. The analysis result management device 1 receives a plurality of static analysis result records from a plurality of static analysis tools 20.FIG. 2 is a diagram showing a hardware configuration of the analysis result management device 1 according to the present embodiment. The analysis result management device 1 is arranged in a network. The analysis result management device 1 and a user terminal 40 can communicate with each other via the network. The type of the network is not limited to a specific type. The network may be, for example, the Internet, an in-house intranet or the like. In the present embodiment, the analysis result management device 1 is arranged in a network, for example. According to another example, the analysis result management device 1 may be provided by a local personal computer (hereinafter, referred to as a local PC). In this case, the local PC has the functions of the analysis result management device 1 and the user terminal 40.The analysis result management device 1 includes a controller (controller) 30 having a CPU 31, a RAM 32, and a ROM 33. The analysis result management device 1 also includes an input unit 34, an output unit 35, a memory 36, and a communication unit 37. The functions of the analysis result management device 1 will be described later. The programs executed by the analysis result management device 1 are also included in the scope of the present invention.A user such as a software developer accesses the analysis result management device 1 via a web browser using the user terminal 40. The user terminal 40 transmits data of a static analysis result to the analysis result management device 1.With reference to FIG. 1, the functions of the analysis result management device 1 will be described. The analysis result management device 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a check result input unit 17.The data input unit 11 receives input of static analysis result data indicating a static analysis result of a source file. The static analysis result is generated by a static analysis tool 20. The static analysis result data is warning data of a source code description that may include bugs. The static analysis result data indicates a location of a syntax error within the source code and a type of the syntax error. The data input unit 11 also receives input of source file data. The reason why the source file is input to the data input unit will be described later. The analysis result management device 1 of the present embodiment also uses the source code data to calculate a hash value.There are various types of static analysis tools 20. The data input unit 11 receives multiple types of data of analysis from different static analysis tools 20. This is because the specifications of the static analysis tools 20 differ from each other and different static analysis tools 20 are good in different analysis areas. By introducing a plurality of static analysis results from a plurality of static analysis tools 20, a highly accurate check can be performed. The data input unit 11 transmits the input static analysis result data to the data converter 12.The data converter 12 includes a data format conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 may have different items and formats (for example, text data, HTML format, etc.) depending on the type of the static analysis tool 20. The data format conversion unit 13 has a function of converting different data formats of different static analysis result data into a common format.The hash value calculation unit 14 has a function of calculating a hash value of a warning included in the static analysis result data. The hash value is specific data calculated based on data concerning a warning and a code included in a line concerning a warning. The warning related data is data related to the warning, and the warning related line is a line related to the warning. The hash value is used as identification information for identifying the warning. The method of calculating the hash value will be described in more detail later.By using the hash value as the identification information of the alert, the same alert can be easily identified across different versions of source files. By using the hash value, it can be avoided that a warning that has already been checked is checked again, whereby the time required for checking the source code is significantly reduced.The database 15 stores static analysis results, verification results and source files. The data format of the static analysis result data is converted by the data converter 12. The static analysis result data is assigned a hash value calculated for the warning, and the static analysis result data assigned the hash value is stored in the database 15.FIG. 3A is a diagram showing an example of the static analysis result data stored in the database 15. The static analysis result data includes a file name, a checker name, a warning message, a tool name, a severity, a row, and a column in association with one hash value. The hash value is identification information identifying the warning, and is calculated based on the warning related data and a code included in the warning related line.The file name is a name of the source file which is a target of static analysis. The verifier name is a name of a verifier that has detected the warning. The static analysis tool 20 has a plurality of inspection algorithms, searches for a code that may include bugs by executing the inspection algorithms, and outputs the warning. The warning message is a message for informing the user of the warning contents.The tool name is a name of the static analysis tool 20 that has detected the warning. The severity constitutes data representing a severity of the warning. The severity is expressed within a numerical range of 0 to 30, and the higher the number, the more severe the warning. The row and column identify the location of the code associated with the alert. The line indicates a line number at which the code associated with the warning starts. The column indicates a column number of the code associated with the alert within the file. Note that the above-described configuration is an example of static analysis result data. The static analysis result data may include data other than the data shown in FIG. 3A.Among the static analysis result data shown in FIG. 3A, the description formats of the checker name, the warning message, the tool name, and the severity vary depending on the static analysis tool 20, and the same code error can be expressed in different formats.FIG. 3B is a diagram showing an example of check result data stored in the database 15. The check result data includes a status, a verifier, a comment, and confirmation date and time associated with a hash value. The hash value corresponds to a hash value included in the static analysis result data, and identifies the warning. The status indicates a checking status of the warning identified by the hash value. "Confirmed" indicates, for example, that the warning has been confirmed, and "Not checked" indicates that the warning has not yet been checked. The verifier indicates a name of a user who has verified the alert and / or changed the status of the alert. The comment is a comment as to which option to take with respect to the warning when the warning is checked by the checker. Confirmation date and time show data regarding the date and time at which the contents of the warning were confirmed. Note that the above-described configuration is an example of check result data. The check result data may include data other than those shown in FIG. 3B.The display unit 16 has a function of displaying the analysis result data stored in the database 15 on the user terminal 40. Specifically, in response to a request from the user terminal 40, the display unit reads the analysis result data from the database 15 and transmits the analysis result data to the user terminal 40.When the verification result input unit 17 receives the verification result data from the user terminal 40, the verification result input unit 17 stores the received verification result in the database 15 in association with the hash value indicating the same warning. Specifically, the check result input unit 17 updates the status, the verifier, the comment, and the confirmation date and time of the warning identified by the hash value.Calculation of Hash ValueNext, a calculation process of the hash value by the hash value calculation unit 14 will be described. The hash value calculation unit 14 calculates a hash value using the warning related data and the code related to the warning (hereinafter, referred to as a warning related code) as inputs. The data concerning a warning includes the file name of the source file, the name of the verifier that has performed the analysis, and the warning message. Note that the above-described configuration is an example of the warning-related data used to calculate the hash value. The data regarding a warning may use other data regarding the warning to calculate the hash value.FIG. 4 is a diagram showing an example of a source code that is a target of static analysis. The calculation of the hash value will be described using the code shown in FIG. 4 as an example. In the example shown in FIG. 4, there may be an error in the code "len++" detected as a warning. The hash value calculation unit 14 calculates a hash value using the warning related data as well as the warning related code "len++" as inputs.Note that the line number is not used in the calculation of the hash value. Since the line number is not used in the calculation of the hash value, even if the line number is shifted in another version of the source code by inserting a blank line, the hash value remains the same, and the user can understand that the hash value indicates the same warning. If the line number is not used in the calculation of the hash value, if the same alert exists in multiple lines, the hash value corresponding to the alerts will be the same as the hash value corresponding to a single alert.Referring to Fig. 4, the codes of the warning lines 1, 2 and 3 are the same. Therefore, the contents of the warning related data (specifically, the file name of the source file, the name of the verifier that has performed the analysis, and the warning notification) for the warnings are the same in the warning lines 1, 2, and 3. In this case, the hash values for the codes in the warning lines 1 to 3 are the same, and identification information is assigned to the warnings in the warning lines 1 to 3, and these are treated as a single warning. Although treatment of the same warnings as a single warning seems acceptable, the analysis result management apparatus 1 of the present embodiment is configured to handle multiple warnings as separate warnings even if they have the same warning contents. The hash value calculation unit 14 calculates a hash value to distinguish the same warnings as shown in FIG. 4.When a hash value (hereinafter referred to as a first hash value) calculated using the data regarding a warning and the code included in the line regarding a warning as inputs is the same as any of the previously calculated hash values, the hash calculation unit 14 calculates a hash value (hereinafter referred to as a second hash value) using the code between a line at which duplication of the hash value is determined to be first starting to a line regarding the warning. Then, the second hash value is set as the hash value corresponding to the warning.FIGS. 5A to 5C are diagrams for explaining the codes to be used in the calculation of the hash values for the warnings in the warning lines 1 to 3. In the description of Figs. 5A to 5C, the code is used to calculate the hash value. However, as described above, the warning related data used as an input for calculating the hash value may be changed as appropriate. FIG. 5A shows the code used to determine the hash of the alert in alert line 1. The code in the fourth line, encircled by a box denoted a, is used as an input for calculating the hash value.FIG. 5B shows the code used to determine the hash of the alert in alert line 2. In addition to the code in box a, the code in the fifth line enclosed by box b and located between warning line 1 and warning line 2 is used as an input for computing the hash value. Duplication of the hash value starts from the warning line 1. FIG. 5C shows the code to be used for calculation of the hash value of the warning in the warning line 3. In addition to the code in box a, the code from lines 5 to 7 in box c located between warning line 1 and warning line 3 is used as an input for computing the hash value. Duplication of the hash value starts from the warning line 1.As shown in Figs. 5A to 5C, even if the same warning is detected for the code "len++", the hash values are distinguished from each other by changing the range of the code used for calculating the hash value.FIG. 6 is a flowchart showing a calculation process executed by the hash value calculation unit 14. The hash value calculation unit 14 first sorts all warnings in the static analysis result data according to the file name and the line number of the warning (S 10). Subsequently, the hash value calculation unit 14 calculates a first hash value using the warning related data and the code in the warning related line as inputs (S 11), and determines whether the first hash value is identical to a hash value calculated previously (S 12).When the same hash value as the first hash value exists (Yes in S 12), the hash value calculation unit 14 calculates the second hash value using (i) the warning related data, (ii) the code in the warning related line, and (iii) the code between the line in which the hash value is first duplicated and the warning related line for which was calculated (S 13). Then, the hash value calculation unit 14 sets the second hash value as the hash value of the warning. Here, spaces, comments, and other parts that do not directly affect the warning may or may not be used in the calculation of the hash value. Subsequently, the hash calculation unit 14 determines whether there is a remaining warning for which the hash value has not yet been calculated (S 14). If there is a warning for which a hash value has not yet been calculated (Yes in S 14), the process returns to S 11 to calculate a first hash value for the remaining warning.When it is determined in S 12 whether a hash value identical to the currently calculated first hash value is present, in response to it being determined that the same hash value does not exist (no in S 12), the first hash value is used as the hash value of the warning that is the calculation target. When it is determined in S 14 whether a warning for which the hash value has not yet been calculated is left, in response to it being determined that there is no warning for which the hash value has not yet been calculated (no in S 14), the calculation process of the hash value for the corresponding static analysis result data is ended.The analysis result management device 1 and the analysis result management method according to the first embodiment have been described above. In the first embodiment, when the calculated first hash value is the same as an already existing hash value, the analysis result management device 1 can avoid duplication of the hash value by calculating the second hash value using the code from the warning line in which the hash value is first duplicated to the warning line corresponding to the calculation target as inputs. Since the code before the line where duplication of the first hash value occurs does not affect the calculation of the second hash value, even if a correction was previously made, it does not affect the analysis of the difference between the different versions. This configuration enables appropriate management of warnings.The software in development is frequently changed with an upgrade of the versions. For this reason, it is important to identify changes and problems. The analysis result management device 1 of the present embodiment manages the analysis result of the source code before and after the upgrading of the software in development and identifies changes and problems. By executing the method for managing the analysis results, it is possible to distinguish different warnings from each other and recognize undetected problems.In the first embodiment described above, in the calculation of the second hash value, the code from the warning line in which the hash value is first duplicated to the warning line corresponding to the calculation target is used as an input. Alternatively, another code range may be used as the input of the hash value calculation. The hash value may be calculated using the code from the first line of the source code to the warning line corresponding to the calculation target, for example.FIGS. 7A to 7C are diagrams showing an example of a code used in the calculation of the second hash value. Figs. 7A to 7C correspond to Figs. 5A to 5C. FIGS. 7A to 7C show calculations of hash values for the warning lines 1 to 3.In FIG. 7A, since the hash value of the alert line 1 is not duplicated, the code regarding alert in the line 1 is used as an input for calculating the hash value. When the hash value of the warning line 2 is calculated, the first hash value calculated using only the code in the warning line 2 is the same as the hash value calculated for the warning line 1. Thus, as shown in FIG. 7B, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box d from the line 1 of the source code to the warning line 2.When the hash value of the warning line 3 is calculated, the first hash value calculated using only the code in the warning line 3 is the same as the hash value calculated for the warning line 1. Thus, as shown in FIG. 7C, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box e from the line 1 of the source code to the warning line 3 as inputs. With this configuration, it is possible to prevent duplication of hash values.According to another example of the code range to be used to calculate the hash value, the code from the previous warning line to the warning line of the calculation target may be used as an input. Fig. 8 shows an example of such calculation of the hash value. In FIG. 8, the three lines starting with "tmp=" correspond to the warning lines 1, 2 and 3.In FIG. 8, since the hash value of the warning line 1 is not duplicated, the code in the warning line 1 is used as an input for calculating the hash value. When the hash value of the warning line 2 is calculated, the first hash value calculated using only the code in the warning line 2 is the same as the hash value calculated using the code in the warning line 1. Thus, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box f from the line subsequent to the warning line 1 to the warning line 2 as inputs.When the hash value of the warning line 3 is calculated, the first hash value calculated using the code in the warning line 3 is the same as the hash value calculated using the code in the warning line 1. Thus, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box g from the line subsequent to the previous warning line 2 to the warning line 3 as inputs. With this configuration, it is possible to prevent duplication of the hash values.Second EmbodimentNext, an analysis result management device according to a second embodiment of the present invention will be described. The basic configuration of the analysis result management device of the second embodiment is the same as that of the analysis result management device 1 of the first embodiment (see FIGS. 1 and 2 ). The analysis result management device according to the second embodiment is different from the analysis result management device according to the first embodiment in that the analysis result management device according to the second embodiment calculates the hash value in consideration of flow information regarding the warning line.FIG. 9 is a diagram for explaining the calculation process executed by the hash value calculation unit 14 of the analysis result management device according to the second embodiment. In FIG. 9, the warning line "case 1: result=a / zero; break;" is enclosed by a box a and warns that a divide by zero (ZERO) can lead to an error. Here, the fact that ZERO is equal to 0 is defined by "#define ZERO 0" as shown in box h.That is, the variable in the code enclosed by box a references the code enclosed in box h, and these two lines are related to each other. When a problem in the source code is detected as a warning, it may be necessary to consider a processing flow that has led to the point at which the problem has occurred. In the present invention, such movement by the source code is referred to as "flow information".When the hash value for the warning line enclosed by the box a is calculated, the hash value calculation unit 14 calculates the hash value using the code in the warning line as well as the code in the line enclosed by the box h as inputs.According to the second embodiment of the analysis result management apparatus, the hash value is calculated in consideration of not only the warning message and the source code but also the flow information concerning the warning line, thereby preventing occurrence of an undetected warning and improving the management quality of the analysis results.In the present embodiment, in addition to the configuration of the analysis result management device 1 of the first embodiment, the hash value is also calculated in consideration of the flow information. The hash value calculation method that avoids duplication of the hash value as in the first embodiment is not necessarily necessary for the calculation of the hash value in consideration of the flow information of the second embodiment. Therefore, in an analysis result management device that enables assignment of the same hash value to a plurality of warnings of the same type, the hash value can be calculated in consideration of the flow information.Third EmbodimentFIG. 10 is a diagram showing a functional configuration of an analysis result management device 3 according to a third embodiment. The basic configuration of the analysis result management device 3 of the third embodiment is similar to that of the analysis result management device 1 of the first embodiment. The analysis result management device 3 of the third embodiment has a warning correspondence table 18. The warning correspondence table 18 is a table showing the correspondence between inspectors who acquire the same type of warnings in static analysis result data generated by a plurality of static analysis tools 20.FIG. 11 is a diagram showing an example of data stored in the warning correspondence table 18. The warning correspondence table 18 shows the correspondence between the checker names of the static analysis tools 20, i.e., the tools X, Y, and Z. In the example shown in FIG. 11, "division by zero" in the tool X, "core.DivideZero" in the tool Y, and "integer division by zero" in the tool Z are correlated with each other. The warning correspondence table 18 correlates identification information with the verifier name of each tool. In FIG. 11, the identification information "INT31-C" is a character string for a rule that "ensures that conversion of an integer (integer) does not result in data loss or mis-interpretation" as defined in the CERT-C coding standard. In this way, a meaningful character string can be used as identification information. Alternatively, meaningless random information may be used when there is no duplication. In FIG. 11, the warning correspondence table 18 stores correspondence between the verifier names of three analysis tools. Instead of the verifier names of the three analysis tools, verifier names of two, four, or more analysis tools may be correlated using the identification information. When an analysis tool is added, the verifier name of the new analysis tool may be registered in the warning correspondence table 18.When the hash value of the warning is calculated, the hash value calculation unit 14 determines whether the checker name that has detected the warning corresponding to the calculation target is recorded in the warning correspondence table 18.In response to the determination that the verifier name is recorded in the warning correspondence table 18, the identification information corresponding to this verifier name is read out, and the hash value is calculated using the identification information as an input instead of the verifier name.FIG. 12 is a diagram for explaining the calculation process performed by the hash value calculation unit 14. The flow shown in FIG. 12 is a detailed process of calculating the first hash value (S 11) or calculating the second hash value (S 13) in the hash value calculation flow shown in FIG. 6.When the hash value is calculated, the analysis result management device 3 of the third embodiment determines whether the verifier name of the verifier that has detected the calculation target warning exists in the warning correspondence table 18 (S 20). In response to the determination that the verifier name exists in the warning correspondence table 18, the process reads out the identification information from the warning correspondence table 18 (S 21), and calculates the hash value using the identification information as an input instead of the verifier name of the warning related data described above (S 23). That is, the file name of the source file and the identification information are used as data concerning a warning. In the analysis result management device 1 of the first embodiment, when the hash value is calculated, the file name of the source file, the name of the verifier that has performed the analysis, and the warning message are used as the warning related data. In the present embodiment, the warning message is not used.When the name of the verifier that has detected the calculation target warning does not exist in the warning correspondence table 18 (No in S 20), the verifier name is referenced (S 22), and the hash value is calculated (S 23). That is, the file name of the source file and the verifier name are used as the data regarding a warning to calculate the hash value.FIG. 13 shows a display example indicating an analysis result managed by the analysis result management device 3. In the analysis result, the hash value identifying the warning is correlated with the file name of the source file in which the warning is acquired, the name of the verifier that acquired the warning, the warning message, the name of the static analysis tool 20 that acquired the warning, the severity indicating the severity of the warning, and check result data of the warning.In the present embodiment, warnings acquired by a plurality of static analysis tools 20 and related to the same code are output as a single warning. Specifically, data of three tools, i.e., tools K, L, and M are correlated with the same hash value in the third row as shown in FIG. 13. Although the warnings are detected by three different static analysis tools 20, they are treated as a single warning, since they correspond to the same code. It is not necessary to handle warnings for each static analysis tool 20. By once inputting the check result, it is possible to set a status indicating that the warning has been dealt with.Conventionally, when a plurality of static analysis tools 20 are used, there is a problem that some warnings are displayed a plurality of times, and thus the determination of the same warnings is time-consuming. According to the present embodiment, it is possible to determine the results of different static analysis tools 20 as the same warning, thereby making the verification more efficient.As shown in FIG. 13, although warnings acquired by inspectors of static analysis tools are treated as a single warning, the warning message and the tool name information remain as data for each static analysis tool 20. Thus, it is possible to refer to the static analysis result generated by each static analysis tool 20.According to the present embodiment, in the calculation of the hash value by the analysis result management device of the first embodiment, the same hash value is assigned to the same warnings acquired by a plurality of static analysis tools by referring to the warning correspondence table 18 (see FIG. 12 ). The technology described in the present embodiment for recognizing warnings from a plurality of static analysis tools as the same warning does not necessarily dictate the configuration of the first embodiment as a prerequisite. The hash value calculation unit 14 may calculate the hash value as shown in FIG. 14.FIG. 14 illustrates a hash value calculation process executed by the analysis result management device 3 according to the third embodiment. The hash value calculation unit 14 first sorts the source files by file name and line number (S 30). Subsequently, the hash value calculation unit determines whether the name of the verifier that has detected the calculation target warning exists in the warning correspondence table 18 (S 31). When it is determined that the checker name exists in the warning correspondence table 18 (Yes in S 31), the hash value calculation unit reads out the identification information from the warning correspondence table 18 (S 31), and calculates the hash value using the identification information as an input instead of the checker name of the data regarding warning (S 34).When the name of the verifier that has detected the calculation target warning does not exist in the warning correspondence table 18 (No in S 31), the verifier name is referenced (S 33), and then the hash value is calculated (S 34).Subsequently, the hash value calculation unit 14 determines whether there is any warning for which the hash value has not yet been calculated (S 35). When it is determined that there is any warning for which the hash value has not yet been calculated (Yes in S 35), the process returns to S 31 and determines whether the name of the verifier that has detected the calculation target warning exists in the warning correspondence table 18. When it is determined that there is no warning for which the hash value has not been calculated yet (no in S 35), the hash value calculation process for the corresponding static analysis result data is ended.The technique described in the present embodiment can also be used for the analysis result management device of the second embodiment.ModificationsThe analysis result management apparatus of the present invention has been described in detail using several embodiments. The analysis result management device of the present invention is not limited to the above-described embodiments. The analysis result management device may prepare a plurality of calculation methods for calculating hash values. The analysis result management device can select only one calculation method matching the design concept of the product project from among a plurality of calculation methods.FIG. 15 is a diagram showing types of inputs used in the calculation of the hash value in a plurality of calculation methods. In the example shown in FIG. 15, three calculation methods 1, 2, and 3 are given. Figure 15 shows the data used as input to a respective calculation method. Specifically, data including the check mark "V" is used for calculating the hash value.The inputs used in the hash value calculation method 1 include a file name, a checker name, a warning message, a code in the line related to warning, and a code within a predetermined range when the hash value is duplicated. The code in the warning line indicates the code in the warning line. The inputs used in the hash value calculation method 2 include a file name, a checker name, a warning message, a code in the warning line, a code in a relevant line, and a code within a predetermined range when the hash value is duplicated. The inputs used in the hash value calculation method 3 include a file name, a verifier name, a warning message, a code in the line relating to a warning. In the calculation method 3, the code within the predetermined range is not used although duplication of the hash value occurs. That is, the calculation method 3 allows duplication of the hash value.By preparing the calculation methods 1, 2, and 3 each allowing duplication of the hash value, the user can select an appropriate calculation method from the prepared options. Specifically, data regarding the calculation methods 1 to 3 are transmitted to the user terminal 40, and the calculation methods are displayed on the user terminal 40. The analysis result management device 1 includes a selection reception unit that receives selection of the calculation method. Specifically, the selection receiving unit receives the selection data of the calculation method input to the user terminal 40, and sets the calculation method according to the selection data.The analysis result management device 3 of the third embodiment can provide a calculation method using the warning correspondence table 18 and a calculation method not using the warning correspondence table 18. As described above, in the warning correspondence table 18, the analysis results of a plurality of static analysis tools 20 are correlated with each other. Thus, the user can select a calculation method for calculating the hash value from the prepared options.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedJP 2004-126 866 A

[0004]

Claims

An analysis result management device (3) that manages data of static analysis results obtained by analyzing a source code using different analysis tools, the analysis result management device comprising: a table (18) that contains a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table further containing identification information associated with the respective different warning descriptions; an input unit (11) that receives the data of the static analysis results of the source code analyzed by the different analysis tools; a hash value calculation unit (14) that acquires warning data including information regarding a target warning included in the received static analysis results and calculates a hash value for the target warning by referring to the table, the target warning being a warning for which the hash value is to be calculated, wherein the hash value calculation unit calculates, in response to a determination that one of the plurality of different warning descriptions corresponds to the target warning, the hash value for the target warning using the identification information associated with the one of the plurality of different warning descriptions in the table without using the one of the plurality of different warning descriptions; a database (15) storing data of the target warning in association with the hash value calculated for the target warning; and a display unit (16) displaying the data stored in the database.The analysis result management apparatus according to claim 1, further comprising: a check result input unit that receives a check result of the target warning, wherein the check result input unit stores, in the database, data of the received check result in association with the hash value calculated for the target warning.The analysis result management device according to claim 1 or 2, wherein when two or more of the plurality of different alert descriptions correspond to the same hash value, the display unit displays the two or more of the plurality of different alert descriptions in association with the same hash value.The analysis result management device according to any one of claims 1 to 3, further comprising: a selection receiving unit that receives a selection of a calculation method of the hash value that allows or does not allow the same hash value for different static analysis results, wherein the hash value calculating unit calculates the hash value using warning data included in the respective different static analysis results input from the different analysis tools without referring to the table.The analysis result management device according to any one of claims 1 to 4, wherein the hash value calculation unit calculates the hash value for the target warning using the warning data, a code in a warning line from which the target warning is detected, and a code in another line related to the warning line within the source code as inputs.An analysis result management method that manages data of static analysis results obtained by analyzing a source code using different analysis tools using an analysis result management device, the analysis result management method being implemented by a computer, and comprising: preparing, by the analysis result management device, a table including a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table further including identification information associated with the respective different warning descriptions; receiving, by the analysis result management device, the data of static analysis results of the source code analyzed by the different analysis tools; acquiring, by the analysis result management device, warning data including information regarding a target warning included in the received static analysis results; calculating, by the analysis result management device, a hash value for the target warning by referring to the table, wherein the target warning is a warning for which the hash value is to be calculated; in response to a determination that one of the plurality of different warning descriptions corresponds to the target warning, calculating the hash value for the target warning using the identification information associated with the one of the plurality of different warning descriptions in the table without using the one of the plurality of different warning descriptions; storing data of the target warning associated with the hash value calculated for the target warning in a database; and displaying the data stored in the database.A computer program for managing data of static analysis results obtained by analyzing a source code using different analysis tools, the computer program causing a computer to function as: a table containing a plurality of different warning descriptions generated by analyzing the same type of warning by the different analysis tools, the table further containing identification information associated with the respective different warning descriptions; an input unit receiving the data of the static analysis results of the source code analyzed by the different analysis tools; a hash value calculation unit that acquires warning data including information regarding a target warning included in the received static analysis results and calculates a hash value for the target warning by referring to the table, the target warning being a warning for which the hash value is to be calculated, wherein the hash value calculation unit calculates, in response to a determination that one of the plurality of different warning descriptions corresponds to the target warning, the hash value for the target warning using the identification information associated with the one of the plurality of different warning descriptions in the table without using the one of the plurality of different warning descriptions; a database storing data of the target warning in association with the hash value calculated for the target warning; and a display unit displaying the data stored in the database.

Citation Information

Patent Citations

  • Description output suppression program analysis system and description output suppression program analysis method

    JP2004126866A